Vice President, Threat Detection Engineer
Singapore, SG
Job Summary
SGX is seeking Senior Vice President/Vice President (Information Security) lead and enhanced our detection capabilities. The Threat Detection Engineer is responsible for designing, developing, tuning, and maintaining cybersecurity detection capabilities across the organization's technology landscape.
This role focuses on identifying malicious activity, improving detection coverage, reducing false positives, and enabling rapid incident response through the deployment of advanced detection rules, analytics, and threat-hunting techniques. Working closely with Security Operations (SOC), Incident Response, Threat Intelligence, Security Engineering, and IT teams, the Threat Detection Engineer continuously enhances the organization's ability to detect and respond to cyber threats.
The candidate will possess strong technical expertise in security detection, relevant platforms, hands-on operational experience, and an engineering mindset focused on improving our speed to react. He/she must demonstrate ability to think strategically about SGX business and operations challenges and possess a keen eye for control improvement through innovative use of technology. The candidate also needs to manage both internal and external customers well, drive discussions with senior management, and have a sound process and technical background to engage the Technology teams.
Job Responsibilities
Detection Engineering
Design, develop, and maintain security detection rules and use cases across and not limited to SIEM, EDR, NDR, and cloud security platforms.
Create detection logic based on known threat actor tactics, techniques, and procedures (TTPs).
Develop behavioral analytics and anomaly detection models.
Map detections to MITRE ATT&CK | MITRE ATLAS framework techniques.
Continuously tune detection rules to improve effectiveness and reduce false positives.
Analyze emerging threats, vulnerabilities, and attack trends.
Translate threat intelligence into actionable detection content.
Assess detection coverage against evolving cyber threats.
Identify gaps in monitoring and recommend improvements.
Work with respective team to develop hypotheses and supporting detection content.
Collaborate with threat hunters to identify previously unknown threats.
Convert successful threat-hunting findings into permanent detections.
Improve event correlation and alerting strategies.
Security Automation
Develop automated detection workflows using SOAR platforms.
Integrate detection content across multiple security controls.
Automate enrichment, triage, and response activities.
Detection validation
Perform adversary emulation and detection testing.
Conduct purple-team exercises with offensive security teams.
Validate detection effectiveness through attack simulation.
Measure detection coverage and effectiveness metrics.
Integration & Engineering
Integrate security tools with other systems (e.g., SIEM, ticketing platforms, CMDB, SOAR) to enable automation and improve operational synergy.
Direct, drive process and documentation improvement in platform operations, escalation procedures, and workflows.
Work closely with Engineering, Infrastructure, Cloud, and SOC teams to ensure deployment of detection logics.
Vendor & Stakeholder Collaboration
Work with internal stakeholders to ensure tools outputs support detection use cases, incident response, audits, and compliance programs.
Expectations:
Sense of urgency for all urgent and important matters and accountable to decision made
Clear vision in mind to innovate and streamline the operations processes and detection ability defined by the organisation.
Passion to deliver sustainable solutions and continued improvement in control and risk mitigation.
Good discipline in timely submission and reporting key metrics and status.
Job Requirements
At least 10 to 15 years of relevant experience, preferably in financial services or asset management industries, with a minimum of 5 years in cybersecurity platforms.
In-depth knowledge and experience in information security policy and principles.
Experience in MAS technology related guidelines such as Technology Risk Management Guidelines, Cyber Hygiene, Outsourcing guidelines etc.
Strong technical knowledge of common security tools (e.g., EDR, SIEM, SOAR, XDR, email security, vulnerability management, cloud security).
Experience tuning detection rules, configuring integrations, and conducting process enhancement.
Demonstrate ability to operate in diverse environments and cultures and enjoys working in challenging and fast-paced environment.
Self-initiated, meticulous, versatile, analytical and inquisitive.
Strong communication and presentation skills to wide and diverse audiences.
Preferred Skills:
Certifications such as CISSP, CISM, GIAC GCIA/GSEC, Microsoft Security certifications, or equivalent.
Experience with security platforms, Endpoint security, Cloud security, detection technologies, analytics & query languages, operating systems and security frameworks (e.g. MITRE ATT&ACK, NIST).
Job Segment:
Executive, VP, Information Security, Risk Management, Cyber Security, Management, Technology, Finance, Security